MEDIUM 5.3 npm
Marked ReDoS due to email addresses being evaluated in quadratic time
GHSA-xf5p-87ch-gxw2
Published · Modified
Description
Versions of marked from 0.3.14 until 0.6.2 are vulnerable to Regular Expression Denial of Service. Email addresses may be evaluated in quadratic time, allowing attackers to potentially crash the node process due to resource exhaustion.
Recommendation
Upgrade to version 0.6.2 or later.
References
- WEB https://github.com/markedjs/marked/pull/1460
- WEB https://github.com/markedjs/marked/commit/b15e42b67cec9ded8505e9d68bb8741ad7a9590d
- PACKAGE https://github.com/markedjs/marked
- WEB https://github.com/markedjs/marked/releases/tag/v0.6.2
- WEB https://snyk.io/vuln/SNYK-JS-MARKED-174116
- WEB https://www.npmjs.com/advisories/812
Ready to move
Start Securing
Free, no credit card | First findings in minutes